THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7gwp-5pfp-969j (critical) — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

[GHSA] GHSA-7gwp-5pfp-969j (critical) — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

highgithub_advisoriesPublished 2026-08-17

GHSA-7gwp-5pfp-969j Severity: critical CVE: CVE-2026-64849

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

### Summary The default MLflow Tracking Server (`mlflow server`, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous `POST /a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7gwp-5pfp-969j